Urban network security multi-dimensional monitoring management system and method
Through the centralized management of threat perception probes, full traffic collectors and threat perception systems, the problem of security products in urban networks being fought independently is solved, and efficient threat detection and multi-dimensional monitoring and management are achieved.
Patent Information
- Application Number
- CN202510444092.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-10
AI Technical Summary
Security products in urban networks fight on their own, and it is difficult to form a joint force, massive security incidents cannot be operated and maintained, unknown threat detection capabilities are limited, and there is a lack of effective means, making it difficult to achieve multi-dimensional monitoring and management.
Threat awareness probe and full-flow collector are used for threat detection and evidence tracing, and centralized management is combined with threat perception system, including unified monitoring, unified management, unified upgrade, centralized policy issuance and threat hunting, and multi-dimensional monitoring is used for multi-dimensional threat analysis module and full-flow collector.
It has achieved efficient management of urban network security, improved threat detection capabilities, tracked and traced the source, and realized centralized management and multi-dimensional monitoring of various types of security products.
Smart Images

Figure CN120342674A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly relates to a multi-dimensional monitoring and management system and method for urban network security. Background Art
[0002] In the field of urban networks, a large number of security products are deployed, such as endpoint antivirus software products, network boundary protection firewalls, IPS products, network detection IDS, sandbox products, etc. The security products operate independently and it is difficult to form a joint force. A huge number of security events cannot be maintained and operated, and deterministic attack clues are missed. The ability to detect unknown threats is limited, and there is a lack of effective means for APT attack detection. There is a lack of tool support for rapid post-event handling, traceability, and attack path restoration of security events. It is difficult to uniformly operate and manage various types of security products, and it is impossible to achieve multi-dimensional monitoring and management of urban network security. Summary of the Invention
[0003] The present invention aims to solve at least one of the technical problems in the above technologies to some extent. For this purpose, the object of the present invention is to provide a multi-dimensional monitoring and management system and method for urban network security, to avoid the independent operation of each security product, and then to centrally manage, improve the threat detection ability, traceability, achieve efficient management of various types of security products, and multi-dimensional monitoring and management of urban network security.
[0004] To achieve the above object, an embodiment of the present invention provides a multi-dimensional monitoring and management system for urban network security, including:
[0005] A threat perception probe, deployed bypassing the center and each node of the monitored urban network unit, for performing threat detection processing;
[0006] A full-flow collector, deployed bypassing the center and each node of the monitored urban network unit, for performing evidence collection and traceability processing;
[0007] A threat perception system, for centrally managing the threat perception probes and full-flow collectors of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy distribution, threat analysis, and threat hunting.
[0008] According to some embodiments of the present invention, the threat perception probe includes:
[0009] A threat perception module, for overall perception of the overall security situation of the currently monitored network, automatically giving high, medium, and low-risk security ratings; providing the global perception ability and threat perception ability for the monitored network;
[0010] The threat detection module adopts a two-way detection engine and implements a trinity detection based on the combination of event feature detection, threat intelligence detection, and sandbox detection; it detects various attack types such as malware exploitation, suspicious behavior, attack exploitation, attack detection, mining events, and APT attack events, and can also detect advanced attacks such as DNS malicious domain name requests, DGA domains, and DNS tunnels; it detects encrypted traffic; it extracts and detects protocol metadata;
[0011] The scenario analysis module is used to preset intelligent analysis scenarios and perform scenario analysis and processing;
[0012] The multi-dimensional threat analysis module is used to perform multi-dimensional threat analysis on attack events;
[0013] The asset awareness module is used to discover assets based on traffic, configure details, and analyze asset vulnerabilities;
[0014] The unknown threat detection module is used to detect unknown threat behaviors by combining dynamic detection and static detection;
[0015] The threat intelligence detection module builds in a threat intelligence library for threat intelligence collision, has a separate threat intelligence perspective, and the threat intelligence can be cloud-checked with one key to view intelligence tags;
[0016] The linkage disposal module is used to dispose of alarms in the monitoring area and can be filtered according to the disposal status; it supports adding white lists and adding white to business-triggered alarms with one key; it can be linked with the same-brand IPS, WAF, firewall, and full-flow traceability and evidence collection devices to block attack behaviors in a linkage manner; when an alarm event is found, it also supports linkage with the same-brand vulnerability scanning device, and a vulnerability scanning task can be created with one key on the alarm event interface to verify vulnerabilities for the detected attack events.
[0017] According to some embodiments of the present invention, the multi-dimensional threat analysis module includes:
[0018] The first analysis module is used to perform threat analysis on attack events from different professional perspectives; the professional perspectives include: attacker perspective, attacked perspective, characteristic event perspective, sample perspective, threat intelligence perspective, ATT&CK perspective, and lateral movement analysis;
[0019] The second analysis module is used to adopt the ATT&CK tactical matrix analysis perspective and automatically mark the color depth of the matrix according to the number of alarm events in the matrix tactics. The matrix includes: reconnaissance, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, lateral movement, collection, command and control, information theft, and impact. The matrix can drill down to the details of the corresponding alarm events;
[0020] An aggregation module for aggregating alerts on attackers, attacked assets, and alert events, capable of viewing the attacker's IP, geographical location, hit intelligence types, most recent attack time, the attacked IP, number of attacks, number of successful attacks, and attack types, supporting viewing of the attacker TOP and the attacker geographical location distribution TOP, and allowing alert filtering according to various dimensions.
[0021] According to some embodiments of the present invention, the full - flow collector includes:
[0022] A full - flow storage module for recording each network traffic data packet from Layer 2 to Layer 7 based on classification and recognition technology, and indexing all network data; providing a session log retrieval function combining protocol metadata and DPI;
[0023] An evidence - collection module for realizing evidence - collection and traceability for Pcap packets and metadata;
[0024] A traffic playback module for playing back historical traffic data packets in the form of a network video recorder, providing them for analysis by security products, allowing flexible playback strategies to be configured, truly restoring the network traffic from Layer 2 to Layer 7, and performing lossless and in - order playback as required.
[0025] According to some embodiments of the present invention, the unified monitoring includes the basic information of the managed security products, CPU / memory disk usage, interface traffic, running time, system version, and signature library version.
[0026] According to some embodiments of the present invention, the unified management includes grouping management, status monitoring, single - sign - on, signature library upgrade management, DNS management, NTP management, configuration backup, and automatic inspection operations for each node security product accessed.
[0027] According to some embodiments of the present invention, the threat analysis includes scenario - based analysis and multi - dimensional correlation analysis; wherein,
[0028] The scenario - based analysis is based on an intelligent event correlation analysis engine to count all the normalized log streams and provides various scenario - based correlation analysis functions, including the attacker's perspective, the attacked - party's perspective, and the alert perspective;
[0029] The multi - dimensional correlation analysis is to perform correlation matching based on a first - type event engine to identify known attacks and obtain a first multi - dimensional correlation analysis result; and perform correlation matching based on a second - type event engine to identify unknown attacks and obtain a second multi - dimensional correlation analysis result.
[0030] According to some embodiments of the present invention, performing correlation matching based on a first - type event engine to identify known attacks and obtain a first multi - dimensional correlation analysis result, including:
[0031] The first type of event engine obtains event information, performs continuous wavelet transform and multi-level wavelet decomposition on the event information, determines the low-frequency component and the high-frequency component, extracts the statistical features of the wavelet coefficients of each layer, and obtains the multi-scale features corresponding to the event information;
[0032] According to each event dimension, filter the feature data related to the event dimension from the multi-scale features corresponding to the event information, and classify the feature data under each event dimension to generate static event features and dynamic event features;
[0033] Perform relevance evaluation on the static event features under each event dimension to generate a first relevance evaluation result; perform change trend analysis and relevance evaluation on the dynamic event features under each event dimension to generate a second relevance evaluation result;
[0034] Query a preset multi-dimensional data relationship graph based on the first relevance evaluation result and the second relevance evaluation result to determine a number of associated nodes and the node attributes of each associated node;
[0035] Generate an association path graph based on a number of associated nodes and the node attributes of each associated node to obtain a first multi-dimensional association analysis result.
[0036] According to some embodiments of the present invention, perform association matching based on the second type of event engine to identify unknown attacks and obtain a second multi-dimensional association analysis result, including:
[0037] The second type of event engine provides a visual rule editor for rule-based association analysis, defines association rules based on logical expressions and statistical conditions, and all log fields can participate in the association, supporting the establishment of single-event rules and multi-event rules to achieve single-event association and multi-event association;
[0038] The second type of event engine performs threat intelligence-based association analysis, which performs real-time association analysis on threat intelligence information and information specific to security events; the threat intelligence information includes malicious IP addresses, malicious URLs, and malicious domain names; the information specific to security events includes source addresses, destination addresses, requested domain names, and payload contents;
[0039] The second type of event engine performs scenario-based association analysis, which comprehensively considers and presents scenario-based association functions including asset attributes, original message content, geographical location information, attack chain, and time sequence;
[0040] Obtain a second multi-dimensional association analysis result according to the rule-based association analysis result, the threat intelligence-based association analysis result, and the scenario-based association analysis.
[0041] According to some embodiments of the present invention, a monitoring and management method for a multi-dimensional urban network security monitoring and management system includes:
[0042] Performing threat detection and processing based on threat perception probes deployed at the center of the monitored urban network unit and bypassing each node;
[0043] Performing forensic traceability processing based on full-flow collectors deployed at the center of the monitored urban network unit and bypassing each node;
[0044] Based on the threat perception system, centrally managing the threat perception probes and full-flow collectors of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy distribution, threat analysis, and threat hunting.
[0045] The present invention proposes a multi-dimensional urban network security monitoring and management system and method, which avoids the individual combat of each security product, and then centrally manages, improves the threat detection ability, traces the source, realizes the efficient management of various types of security products, and conducts multi-dimensional monitoring and management of urban network security.
[0046] Other features and advantages of the present invention will be described in the following specification, and part of them will become obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification and the drawings.
[0047] The technical solutions of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings
[0048] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention, and do not constitute a limitation to the present invention. In the drawings:
[0049] Figure 1 is a block diagram of a multi-dimensional urban network security monitoring and management system according to an embodiment of the present invention;
[0050] Figure 2 is a schematic diagram of a multi-dimensional urban network security monitoring and management system according to another embodiment of the present invention;
[0051] Figure 3 is a flowchart of a multi-dimensional urban network security monitoring and management method according to an embodiment of the present invention. Detailed Embodiments
[0052] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0053] As Figure 1 - Figure 2 shown, an embodiment of the present invention proposes a multi-dimensional monitoring and management system for urban network security, including:
[0054] Threat perception probes, deployed bypassing the center and each node of the monitored urban network unit, for threat detection and processing;
[0055] Full traffic collectors, deployed bypassing the center and each node of the monitored urban network unit, for forensic traceability processing;
[0056] A threat perception system, for centrally managing the threat perception probes and full traffic collectors of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy issuance, threat analysis, and threat hunting.
[0057] The working principle of the above technical solution: The multi-dimensional monitoring and management system for urban network security includes: threat perception probes, full traffic collectors, and a threat perception system. The threat perception probes and full traffic collectors in the composition scheme are respectively deployed bypass to collect user service traffic. The threat perception probes are responsible for threat detection, and the full traffic collectors are responsible for forensic traceability. When the threat perception probe product discovers a threat behavior, it can link the full traffic collector to achieve one-key automated attack full-volume message forensics and quickly conduct attack research and judgment analysis. For each stage of the attack chain, the original data can be retrieved through the full traffic collector, and finally, the complete attack process can be traced from the trace information.
[0058] The beneficial effects of the above technical solution: Avoid each security product fighting alone, and then conduct centralized management, improve threat detection capabilities, trace and trace, realize the efficient management of various types of security products, and conduct multi-dimensional monitoring and management of urban network security.
[0059] According to some embodiments of the present invention, the threat perception probe includes:
[0060] A threat perception module, for overall perception of the overall security situation of the currently monitored network, automatically giving high, medium, and low-risk security ratings; providing the global perception ability and threat perception ability for the monitored network;
[0061] A threat detection module, using a two-way detection engine, realizing three-in-one detection based on the combination of event feature detection + threat intelligence detection + sandbox detection; detecting various attack types such as malicious software utilization, suspicious behavior, attack utilization, attack detection, mining events, and APT attack events, and at the same time, detecting advanced attacks such as DNS malicious domain name requests, DGA domains, and DNS tunnels; detecting encrypted traffic; extracting and detecting protocol metadata;
[0062] A scenario analysis module for presetting intelligent analysis scenarios and performing scenario analysis processing;
[0063] A multi-dimensional threat analysis module for performing multi-dimensional threat analysis on attack events;
[0064] An asset perception module for performing asset discovery, detail configuration based on traffic for assets, and analyzing asset vulnerabilities;
[0065] An unknown threat detection module for detecting unknown threat behaviors by combining dynamic detection and static detection;
[0066] A threat intelligence detection module with a built-in threat intelligence library for threat intelligence collision, having a separate threat intelligence perspective. At the same time, threat intelligence can be queried on the cloud with one key to view intelligence tags;
[0067] A linkage handling module for handling alarms in the monitored area, which can be filtered according to the handling status; supports adding a whitelist to add a white list to business-triggered alarms with one key; can be linked with the same brand's IPS, WAF, firewall, and full-flow traceability and evidence collection devices to block attack behaviors through linkage; when an alarm event is discovered, it also supports linkage with the same brand's vulnerability scanning device, and a vulnerability scanning task can be created with one key on the alarm event interface to verify vulnerabilities for the monitored attack events.
[0068] The working principle and beneficial effects of the above technical solutions: The threat perception module provides the global perception ability of the monitored network, can display the number of attacks, attack trends, high-value events, attack stage analysis, attack directions on the global map, and can view the attack trend. It provides the threat perception ability for external attacks, lateral attacks, malicious external connections, details of compromised hosts, and security postures of transmitted files in the monitored network. Threat information such as external attack trends, the number of internal network zombie, worm, and Trojan events, the number of internal network scanning events, the top attacking IPs, the top attacked IPs, the top external connection countries, the top external connection C2s, the top external connection hosts, and external connection trend charts can be viewed.
[0069] The threat detection module adopts a two-way detection engine. Compared with traditional detection methods, it can directly give whether the attack result is successful, and at the same time saves the alarm data packets, providing the ability of threat traceability and evidence collection. It combines event feature detection, threat intelligence detection, and sandbox detection, and has the trinity detection ability. It can detect attack types such as malware exploitation, suspicious behavior, attack exploitation, attack detection, mining events, and APT attack events. At the same time, it can detect advanced attacks such as DNS malicious domain name requests, DGA domains, and DNS tunnels. In the face of encrypted traffic, the threat perception probe can not only decrypt TLS encrypted traffic by importing certificates, but also support the use of JA3 fingerprint detection method to detect malware. It supports the extraction and detection of protocol metadata, and can extract metadata for common protocols such as TCP, HTTP, DNS, ICMP, SMTP, POP3, FTP, SMB, IP, TLS, UDP, PPTP, L2TP, MySQL, Telnet, ARP, WebMail, MSSQL, Oracle, IPSecVPN, IMAP, IPV6, etc.
[0070] The scenario analysis module has no less than 15 intelligent analysis scenarios, including compromised host scenarios, attack chain restoration analysis scenarios, weak passwords in the internal network scenarios, vulnerability perception scenarios, scenarios of high-risk ports open to the outside world, scenarios of malicious domain names actively connecting to the outside, DGA domain name scenarios, DNS covert tunnel scenarios, malicious email behavior analysis scenarios, special analysis scenarios for virtual currency mining, internal network botnet attacks scenarios, brute force cracking scenarios, scanning and detection scenarios, scenarios of suffering from DDOS attacks, WEB attack detection scenarios, suspicious behavior scenarios, etc. The threat perception probe can discover effective attacks and valuable clues from the alarms, and can completely restore the attack chain. Using the current deterministic clues as the center, with the event name, event tags, attacker, attacked party, attack result, etc. as the basic information origin, retrieve forward and backward, and use historical traffic data to discover the association between deterministic clues and suspicious behavior clues, so as to expand the analysis of the entire attack chain, and map with the ATT&CK model to generate an attack behavior portrait, forming a customizable web visualization topology.
[0071] Through intelligent scenario analysis, project the security monitoring ability into each business scenario to meet the multi-dimensional security monitoring needs. For example, virtual currency mining, which the country is cracking down on vigorously, the threat perception probe has a special analysis scenario for mining. Through the mining analysis scenario, you can directly view the pie chart of the distribution of mining currencies, the statistical chart of the mining stage, the mining trend chart, and the activity of mining hosts, and you can view mining alarm information, mining occurrence time, mining host address, mining pool address, mining stage, mining duration and other mining event information, and directly locate all mining hosts in the monitoring area.
[0072] The asset perception module can discover assets based on traffic for assets, and automatically classify the discovered assets into corresponding asset groups according to the IP segments to which the assets belong. It supports the use of public networks for private purposes and can configure the details of assets, including asset names, asset groups, asset types, intranet markings, important asset tags, external network IP tags, system information, location information, asset running services, responsible persons, contact information, physical locations, etc. It can analyze the vulnerabilities of assets, including high-risk port access, weak password login events, and asset vulnerability perception. It can view information such as the most recent access time, access IP, access account, weak password used for login, IP of the accessed asset, asset group to which the asset belongs, asset name, protocol used for login, password strength, and number of accesses for assets with weak passwords logged in. At the same time, it supports downloading the original packets during the weak password login process to provide traceability and evidence retention.
[0073] The unknown threat detection module uses a combination of dynamic detection and static detection to detect unknown threat behaviors. It has the ability to detect more than 100 file format sandboxes, supports customizing file types, and can restore and sandbox-detect files transmitted by SMTP, IMAP, FTP, POP3, SMB, and HTTP. The sandbox can automatically output sample reports, and the sandbox sample reports and original samples can be downloaded. The sample reports automatically display malicious sample threat labels, and the system can automatically give a malicious score based on the behavior of malicious samples and can expand the malicious behavior of the samples with one key.
[0074] It can detect compressed files, support at least 10 layers of decompression for compressed files, can detect anti-sandbox malicious samples, can detect no less than 5 anti-sandbox behaviors, and at the same time supports displaying the malicious code type with Chinese labels for further sample analysis. It has more than seventy virtual sandbox detection environments to meet various unknown threat detection scenarios and supports full coverage of Windows, Linux, Android, and Zhongbiao Kirin systems.
[0075] It supports displaying the malicious code type with Chinese labels and supports retrieving according to Chinese labels. It can customize YARA rules for detection, can detect the network behavior of file samples, record the network communication sessions when the files are running, and support online viewing of communication session details such as the destination IP, destination port, hexadecimal and ASCII format packet contents, etc. It can download files for sensitive behaviors such as releasing PE files, deleting folders, modifying files, copying itself, and infecting files; it supports detailed recording of monitoring operations on the file system, including detecting behaviors such as writing files (folders), deleting files (folders), and reading files (folders).
[0076] The threat perception probe has rich security analysis reports, providing rich report content for users and operation and maintenance personnel. It supports manually generating single reports and also supports generating reports periodically, greatly reducing the maintenance cost and the work intensity of administrators.
[0077] The threat perception probe has a data reporting function, and supports sending sample detection logs, feature detection logs, metadata logs, and JA3 fingerprint logs to the threat perception system through the Kafka interface, and then the centralized management sub-center performs secondary unified analysis and display.
[0078] According to some embodiments of the present invention, the multi-dimensional threat analysis module includes:
[0079] The first analysis module is used to perform threat analysis on attack events from different professional perspectives; the professional perspectives include: attacker perspective, attacked party perspective, feature event perspective, sample perspective, threat intelligence perspective, ATT&CK perspective, and lateral movement analysis;
[0080] The second analysis module is used to adopt the ATT&CK tactical matrix analysis perspective, and automatically mark the color depth of the matrix according to the number of alarm events in the matrix tactics. The matrix includes: reconnaissance, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, lateral movement, collection, command and control, information stealing, and impact. The matrix can drill down to the details of the corresponding alarm events;
[0081] The aggregation module is used to perform alarm aggregation on attackers, attacked assets, and alarm events. It can view the attacker's IP, geographical location, hit intelligence type, recent attack time, attacked party's IP, number of attacks, number of successful attacks, and attack type. It supports viewing the attacker TOP, attacker geographical location distribution TOP, and can perform alarm screening according to various dimensions.
[0082] According to some embodiments of the present invention, the full traffic collector includes:
[0083] The full traffic storage module is used to record each network traffic data packet from layer 2 to layer 7 based on classification and recognition technology, and establish an index for all network data; it provides a session log retrieval function combining protocol metadata and DPI;
[0084] The forensics module is used to achieve forensics traceability for Pcap packets and metadata;
[0085] The traffic playback module is used to playback historical traffic data packets in the form of a network video recorder, provide them to security products for analysis, and can configure flexible playback strategies to truly restore the network traffic from layer 2 to layer 7, and perform lossless and in-order playback as needed.
[0086] Working principle and beneficial effects of the above technical solution: To more comprehensively collect evidence of attack behaviors, the full traffic collector classifies, identifies, and records each network traffic data packet from Layer 2 to Layer 7, and indexes all network data to ensure that the original scenario of network security events can be restored completely and truthfully. At the same time, the full traffic storage module also provides a session log retrieval function that combines protocol metadata and DPI. The session log records the start and end states of protocol sessions, as well as detailed statistics related to traffic. Combining with DPI technology, accurate classification of specific applications is completed. Through the retrieval of session logs, accurate data related to relevant activities can be efficiently extracted from massive data, helping security analysts and investigators quickly find the original evidence of anomalies and threats, and realizing uncontested evidence extraction.
[0087] Real-time storing and recording the traffic data of the entire network will pose great challenges to the storage and retrieval performance of the product. Many security products on the market currently have a common drawback, that is, in the face of retrospective queries of large amounts of data, they are very slow, even so slow that the product cannot be used.
[0088] The original message forensics module of the full traffic collector has independently developed high-performance storage and retrieval algorithms, has the fastest data retrieval performance in the industry, with a retrieval speed of up to 5TB / second, can achieve second-level forensics of threats, and improve the efficiency of threat analysis.
[0089] The metadata forensics and traceability module can parse the application protocol layer of network traffic in real time and in full volume, and extract metadata for network operation and security operation and maintenance personnel to conduct attack positioning and traceability analysis. After precise protocol identification by the DPI engine, the metadata parsing engine extracts key fields from the application protocol to generate metadata.
[0090] The application layer protocols for which the full traffic system can extract metadata are as follows:
[0091] HTTP: More than 60 fields such as the host, URL, cookie, method of HTTP requests, and response status codes.
[0092] MAIL: SMTP, IMAP, POP3 protocols for mail transmission, and more than 20 fields such as the senders and receivers of emails, email subjects, attachment names and types.
[0093] DNS: More than 20 fields such as the type of DNS queries, domain names, and domain name resolution addresses.
[0094] Database protocols: Commands and results of common database operations such as MYSQL and ORACLE, and can parse more than 20 fields.
[0095] Socks5 Proxy: Version of Socks5 proxy, authentication method, command code, target host information, etc.
[0096] FTP: Logged-in users of FTP, operation commands, and results.
[0097] TELNET: Logged-in users of TELNET and operation commands.
[0098] SSH: Version information of the client and server for SSH login, and more than 20 fields such as the server key type.
[0099] TLS: Version, cipher suite, certificate information, and more than 20 fields for encrypted transmission of TLS and SSL.
[0100] Customization: Users can configure the fields to be extracted according to their needs and customize the parsing rules to achieve flexible parsing of application layer metadata.
[0101] Security personnel can quickly conduct forensic tracing of attack behaviors based on the characteristics of application layer metadata.
[0102] According to some embodiments of the present invention, the unified monitoring includes basic information of the managed security products, CPU / memory / disk usage, interface traffic, running time, system version, and feature library version.
[0103] Beneficial effects of the above technical solution: Thus, the workload of operation and maintenance personnel is significantly reduced, achieving the purpose of unified monitoring through one interface.
[0104] According to some embodiments of the present invention, the unified management includes grouping management, status monitoring, single sign-on, feature library upgrade management, DNS management, NTP management, configuration backup, and automatic inspection operations for the connected node security products.
[0105] Beneficial effects of the above technical solution: Through the centralized management function, all connected security products can be operated uniformly, saving time and effort.
[0106] In one embodiment, unified upgrade: Since network security is a dynamic process, for the vast majority of security products, the upgrade of the feature library / signature library / intelligence library is an extremely important operation and maintenance task. Conventionally, upgrading the feature library for a large number of different types of security products is quite cumbersome. If configured for each product to perform external connection upgrade independently, there will be a large number of Internet exposure surfaces, and each time a new product is launched or the network changes, the access control policy needs to be reconfigured again, increasing the operation and maintenance burden.
[0107] The threat perception system itself can serve as a unified upgrade center for all nodes. On the one hand, it can synchronize upgrade packages of various security products from the cloud through proxy or direct connection. Users only need to configure the access permission that only allows the centralized management and distribution center to access externally to meet the feature library requirements of all products. For newly launched security products, there is no need to change the access control rules. They can directly point the upgrade server to the centralized management and distribution center. On the other hand, it will configure and actively respond to the upgrade requests of each product and form statistical records for operation and maintenance personnel to analyze.
[0108] In one embodiment, unified policy distribution: The threat perception system supports the unified policy distribution function.
[0109] According to some embodiments of the present invention, the threat analysis includes scenario-based analysis and multi-dimensional correlation analysis; wherein,
[0110] The scenario-based analysis is based on an intelligent event correlation analysis engine to count all the normalized log streams and provides various functions of scenario-based correlation analysis, including the attacker's perspective, the victim's perspective, and the alert perspective;
[0111] The multi-dimensional correlation analysis is to perform correlation matching based on the first type of event engine to identify known attacks and obtain the first multi-dimensional correlation analysis result; perform correlation matching based on the second type of event engine to identify unknown attacks and obtain the second multi-dimensional correlation analysis result.
[0112] The working principle of the above technical solution: The scenario-based analysis is convenient for presenting to security analysts in a specific scenario. The first type of event engine is an engine for identifying known attacks. The second type of event engine is an engine for identifying unknown attacks and is used for predicting unknown attacks.
[0113] The beneficial effects of the above technical solution: Through the combined analysis of scenario-based analysis and multi-dimensional correlation analysis, the efficiency and accuracy of threat analysis are improved. When performing multi-dimensional correlation analysis, different engines are used for correlation matching of known attacks and unknown attacks, which improves the accuracy of attack identification.
[0114] According to some embodiments of the present invention, performing correlation matching based on the first type of event engine to identify known attacks and obtain the first multi-dimensional correlation analysis result, including:
[0115] The first type of event engine obtains event information, performs continuous wavelet transform and multi-layer wavelet decomposition on the event information, determines the low-frequency component and the high-frequency component, extracts the statistical features of the wavelet coefficients of each layer, and obtains the multi-scale features corresponding to the event information;
[0116] According to each event dimension, filter the feature data related to the event dimension from the multi-scale features corresponding to the event information, and classify the feature data under each event dimension to generate static event features and dynamic event features;
[0117] Perform a relevance assessment on the static event features under each event dimension to generate a first relevance assessment result; perform a change trend analysis and a relevance assessment on the dynamic event features under each event dimension to generate a second relevance assessment result;
[0118] Query a preset multi-dimensional data relationship graph based on the first relevance assessment result and the second relevance assessment result to determine a number of associated nodes and the node attributes of each associated node;
[0119] Generate an association path graph based on a number of associated nodes and the node attributes of each associated node to obtain a first multi-dimensional association analysis result.
[0120] The working principle and beneficial effects of the above technical solution: The first type of event engine decomposes the event signal into sub-bands of different frequencies through continuous wavelet transform (CWT). The low-frequency component (approximation coefficient) reflects the baseline behavior of the event, and the high-frequency component (detail coefficient) captures the mutation characteristics, obtaining the multi-scale features corresponding to the event information.
[0121] According to each event dimension, filter the feature data related to the event dimension from the multi-scale features corresponding to the event information, and classify the feature data under each event dimension to generate static event features and dynamic event features; for static features (such as event duration, intensity), describe the inherent attributes through statistical distribution. Use cosine similarity or Jaccard coefficient to measure the similarity between feature vectors. Dynamic features (such as change rate, periodicity) need to combine time series analysis (such as ARIMA model) to evaluate the evolution trend. Analyze the time lag relationship between features through the cross-correlation function, such as the time delay pattern of malware propagation. Query a preset multi-dimensional data relationship graph based on the first relevance assessment result and the second relevance assessment result, and accurately determine a number of associated nodes and the node attributes of each associated node in a static and dynamic combined manner; generate an association path graph based on a number of associated nodes and the node attributes of each associated node to obtain a first multi-dimensional association analysis result. Improve the ability of correlation analysis for known attacks and reduce the dependence on manual rule maintenance at the same time.
[0122] According to some embodiments of the present invention, perform association matching based on the second type of event engine to identify unknown attacks, and obtain a second multi-dimensional association analysis result, including:
[0123] The second type of event engine is based on rule-based association analysis. It provides a visual rule editor to define association rules based on logical expressions and statistical conditions. All log fields can participate in the association. It supports the establishment of single event rules and multi-event rules to achieve single event association and multi-event association.
[0124] The second type of event engine is based on the correlation analysis of threat intelligence, and performs real-time correlation analysis between threat intelligence information and security event specific information; the threat intelligence information includes malicious IP addresses, malicious URLs, and malicious domain names; the security event specific information includes source address, destination address, request domain name, and payload content;
[0125] The second type of event engine is based on scenario-based correlation analysis, comprehensively considering and presenting scenario-based correlation functions including asset attributes, original message content, geographic location information, attack chain, and time sequence;
[0126] According to the rule-based correlation analysis results, the threat intelligence-based correlation analysis results and the scenario-based correlation analysis results, a second multi-dimensional correlation analysis result is obtained.
[0127] Working principle and beneficial effects of the above technical solution: The rule editor allows users to define association rules through logical expressions and statistical conditions. These rules can be applied to a single event (single event rule) or multiple events (multi-event rule). Logical expressions involve comparisons and combinations of event attributes, while statistical conditions involve the frequency and trend of event occurrence. Real-time association of threat intelligence information (such as malicious IP addresses, URLs, domain names) with specific information of security events (such as source addresses, destination addresses, request domain names, and payload content) helps to quickly identify known threat patterns. This association involves exact matching (such as IP address matching) or fuzzy matching (such as domain name similarity detection). The scenario-based association function comprehensively considers factors such as asset attributes, original message content, geographic location information, attack chain, and timing. This analysis helps to understand the full picture of the attack, including the attacker's goals, attack paths, and attack timelines. Combining the above three types of association analysis results, a multi-dimensional association analysis result is generated. This result includes information on dimensions such as attack type, attack source, attack target, and attack impact, which helps the security team to comprehensively assess threats and take corresponding measures. The correlation matching method based on the second type of event engine can comprehensively identify unknown attacks and generate detailed multi-dimensional correlation analysis results by combining rules, threat intelligence and scenario analysis. This method improves the accuracy and efficiency of threat detection.
[0128] like Figure 3 As shown, according to some embodiments of the present invention, a monitoring and management method of a city network security multi-dimensional monitoring and management system includes steps S1-S3:
[0129] S1. Perform threat detection and processing based on threat perception probes deployed at the center of the network units in the monitored city and bypasses of each node;
[0130] S2. Perform forensic traceability processing based on full - traffic collectors deployed at the center of the network units in the monitored city and bypasses of each node;
[0131] S3. Perform centralized management on the threat perception probes and full - traffic collectors of each node based on the threat perception system; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy distribution, threat analysis, and threat hunting.
[0132] Beneficial effects of the above - mentioned technical solution: Avoid each security product operating independently, and then conduct centralized management to improve threat detection capabilities, trace and trace, achieve efficient management of various types of security products, and conduct multi - dimensional monitoring and management of urban network security.
[0133] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.
Claims
1. A multi-dimensional monitoring and management system for urban network security, characterized in that, Including: Threat perception probes, deployed bypassing the center and each node of the monitored urban network unit, for threat detection and processing; Full-flow collectors, deployed bypassing the center and each node of the monitored urban network unit, for forensic traceability processing; A threat perception system for centrally managing the threat perception probes and full-flow collectors of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy distribution, threat analysis, and threat hunting.
2. The urban network security multi-dimensional monitoring and management system according to claim 1, characterized in that, The threat perception probe includes: A threat perception module for overall perception of the overall security posture of the currently monitored network, automatically giving high, medium, and low-risk security ratings; providing global perception and threat perception capabilities for the monitored network; A threat detection module that uses a two-way detection engine to achieve three-in-one detection based on a combination of event feature detection, threat intelligence detection, and sandbox detection; detecting various attack types such as malware exploitation, suspicious behavior, attack exploitation, attack detection, mining events, and APT attack events, and at the same time detecting advanced attacks such as DNS malicious domain name requests, DGA domains, and DNS tunnels; detecting encrypted traffic; extracting and detecting protocol metadata; A scenario analysis module for presetting intelligent analysis scenarios and performing scenario analysis and processing; A multi-dimensional threat analysis module for multi-dimensional threat analysis of attack events; An asset perception module for asset discovery, detail configuration based on traffic, and vulnerability analysis of assets; An unknown threat detection module for detecting unknown threat behaviors by combining dynamic detection and static detection; A threat intelligence detection module with a built-in threat intelligence library for threat intelligence collision, having a separate threat intelligence perspective, and at the same time, threat intelligence can be queried in the cloud with one key to view intelligence tags; A linkage disposal module for disposing of alarms in the monitored area, which can be filtered according to the disposal status; supports adding white lists and adding white to business-triggered alarms with one key; can be linked with the same brand of IPS, WAF, firewall, and full-flow traceability and forensics equipment to block attack behaviors in a linkage manner; when an alarm event is detected, it also supports linkage with the same brand of vulnerability scanning equipment, and a vulnerability scanning task can be created with one key on the alarm event interface to verify vulnerabilities for the detected attack events.
3. The urban network security multi-dimensional monitoring and management system according to claim 2, characterized in that, The multi-dimensional threat analysis module includes: A first analysis module for threat analysis of attack events from different professional perspectives; the professional perspectives include: attacker perspective, attacked party perspective, characteristic event perspective, sample perspective, threat intelligence perspective, ATT&CK perspective, and lateral movement analysis; A second analysis module for using the ATT&CK tactical matrix analysis perspective to automatically mark the color depth of the matrix according to the number of alarm events in the tactical matrix. The matrix includes: reconnaissance, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, lateral movement, collection, command and control, information theft, and impact. The matrix can drill down to the details of the corresponding alarm events; Aggregation module, used for aggregating alerts for attackers, attacked assets, and alert events. It can view attacker IP, geographical location, intelligence types hit, most recent attack time, attacked IP, number of attacks, number of successful attacks, and attack types. It supports viewing attacker TOP and geographical location distribution TOP of attackers, and can perform alert filtering according to various dimensions.
4. The urban network security multi-dimensional monitoring and management system according to claim 1, characterized in that The full - traffic collector includes: Full - traffic storage module, which records each network traffic packet from layer 2 to layer 7 based on classification and recognition technology, and indexes all network data; provides a session log retrieval function combining protocol metadata and DPI. Forensics module, used for forensic traceability of Pcap packets and metadata. Traffic playback module, used to playback historical traffic packets in the form of a network video recorder, provided to security products for analysis. It can configure flexible playback strategies, truly restore the network traffic from layer 2 to layer 7, and perform lossless and in - order playback as needed.
5. The urban network security multi-dimensional monitoring and management system according to claim 1, characterized in that The unified monitoring includes basic information of managed security products, CPU / memory / disk usage, interface traffic, running time, system version, and signature library version.
6. The multi-dimensional monitoring and management system for urban network security according to claim 1, characterized in that The unified management includes grouped management, status monitoring, single sign - on, signature library upgrade management, DNS management, NTP management, configuration backup, and automatic inspection operations for each node security product accessed.
7. The multi-dimensional monitoring and management system for urban network security according to claim 1, characterized in that The threat analysis includes scenario - based analysis and multi - dimensional correlation analysis; among which, The scenario - based analysis is based on an intelligent event correlation analysis engine, which statistically analyzes all normalized log streams and provides multiple scenario - based correlation analysis functions, including attacker perspective, attacked - party perspective, and alert perspective. The multi - dimensional correlation analysis performs correlation matching based on the first - type event engine to identify known attacks and obtain the first multi - dimensional correlation analysis result; performs correlation matching based on the second - type event engine to identify unknown attacks and obtain the second multi - dimensional correlation analysis result.
8. The urban network security multi-dimensional monitoring and management system according to claim 7, characterized in that, Performing correlation matching based on the first - type event engine to identify known attacks and obtain the first multi - dimensional correlation analysis result, including: The first - type event engine obtains event information, performs continuous wavelet transform and multi - layer wavelet decomposition on the event information, determines the low - frequency component and high - frequency component, extracts the statistical features of wavelet coefficients of each layer, and obtains the multi - scale features corresponding to the event information. According to each event dimension, filter the feature data related to the event dimension from the multi - scale features corresponding to the event information, and classify the feature data under each event dimension to generate static event features and dynamic event features. Perform relevance evaluation on the static event features under each event dimension to generate the first relevance evaluation result; perform change trend analysis and relevance evaluation on the dynamic event features under each event dimension to generate the second relevance evaluation result. Query a preset multi - dimensional data relationship graph based on the first relevance evaluation result and the second relevance evaluation result to determine several associated nodes and the node attributes of each associated node. Generate an association path graph based on several associated nodes and the node attributes of each associated node to obtain the first multi - dimensional correlation analysis result.
9. The urban network security multi-dimensional monitoring and management system according to claim 7, characterized in that Perform correlation matching based on the second type of event engine to identify unknown attacks and obtain the second multi-dimensional correlation analysis results, including: The correlation analysis based on rules of the second type of event engine provides a visual rule editor to define correlation rules based on logical expressions and statistical conditions. All log fields can participate in the correlation, supporting the establishment of single-event rules and multi-event rules to achieve single-event correlation and multi-event correlation; The correlation analysis based on threat intelligence of the second type of event engine performs real-time correlation analysis on threat intelligence information and specific information of security events; the threat intelligence information includes malicious IP addresses, malicious URLs, and malicious domain names; the specific information of security events includes source addresses, destination addresses, requested domain names, and payload contents; The correlation analysis based on scenarios of the second type of event engine comprehensively considers and presents the scenario-based correlation function including asset attributes, original message content, geographical location information, attack chain, and time sequence; According to the correlation analysis results based on rules, the correlation analysis results based on threat intelligence, and the correlation analysis based on scenarios, obtain the second multi-dimensional correlation analysis results.
10. The monitoring and management method of the urban network security multi-dimensional monitoring and management system according to any one of claims 1-9, characterized in that, Including: Perform threat detection and processing based on the threat perception probes deployed bypassing the center of the network units and each node in the monitored city; Perform forensic tracing and processing based on the full-flow collectors deployed bypassing the center of the network units and each node in the monitored city; Centrally manage the threat perception probes and full-flow collectors of each node based on the threat perception system; the centralized management includes unified monitoring, unified management, unified upgrade, centralized policy distribution, threat analysis, and threat hunting.
Citation Information
Patent Citations
Comprehensive urban network space governance system
CN107958322A
Network security perception system and method, and readable storage medium
CN107995162A
Tenant-based security capability and security service chain management platform
CN112291232A
Intelligent security event association analysis system for threat scene
CN112738016A
Network security intelligent analysis method, system and device and storage medium
CN115834221A
Cited By
Optical fiber network data flow security management and control platform
CN120614218A